Our standard penetration test report follows a proven formula that includes:
To better understand this deliverable, you may download our sample report. Our main goal with this document structure is to provide high-quality, actionable information.
Minor variations in the report format won't significantly change the overall effort for the reporting phase of a penetration test. However, the following factors could make a difference, so be sure to bring these up:
There's a difference in the amount of effort needed to build a report for a typically sized penetration test and one that is unusually large or entails unusual complexities. Some examples include:
There may be circumstances where splitting the test findings into more than one report is desirable. For example, if we are testing several web applications simultaneously and you prefer a separate report for each application, this will increase the effort. We can usually accommodate some report splitting without increasing the cost, but the amount of effort increases slightly with each additional report.
Your circumstances may require specialized reporting that does not fit the standard report format. For example, you may have unique requirements defined by internal governance or third-party regulatory obligations. We are happy to accommodate any special requirements that are clearly defined while scoping the work.
Some examples of special reporting requirements include: